Security

How we protect the service and customer data.

A plain-language summary of the controls currently designed into the service. Security claims are kept to measures we can operate and verify.

Last updated July 2026

Payments

When live payments are enabled, card details are collected by the configured payment processor’s secure components. esimterra is designed not to receive or store a full card number.

The checkout identifies the available payment method and final amount before submission. Payment confirmation identifiers may be stored with the order for support, accounting and fraud prevention.

Personal data

We limit collection to data needed for orders, delivery, account features, support, security and legal obligations. Required service providers receive only the data needed for their role.

We do not sell personal information. The privacy policy explains categories, purposes, recipients, retention and rights in more detail.

Read the privacy policy

Accounts and access

Customer sign-in uses time-limited passwordless verification. Sensitive server actions validate identity and authorization again instead of trusting browser state alone.

Administrative access is separated from customer access, protected with least-privilege controls and audited where the application records a privileged action.

Infrastructure

The application uses encrypted HTTPS connections, server-side secret storage and database access rules. Supplier credentials and service-role keys stay out of browser bundles and public responses.

No system is perfectly secure. Controls, dependencies and incident procedures must continue to be reviewed as the service moves from mock integrations to production.

Report a security issue

Send a clear description and safe reproduction steps to security@esimterra.com. Do not access other customers’ data, disrupt the service or include live credentials in the report.

Email support